Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Coding Tools Expose Sensitive Data on GitHub

AI Coding Tools Expose Sensitive Data on GitHub

Posted on September 30, 2026 By CWS

AI coding tools have inadvertently exposed over 13,000 internal images from more than 300 organizations on GitHub, according to security firm Glow. The exposed data included customer billing records and unreleased features, raising significant security concerns.

Extent of the Data Exposure

Glow’s researchers identified the sensitive images, which were often stored in developers’ personal GitHub accounts, unnoticed by company security teams. The breach affected a range of companies, including a major tech firm, a leading AI lab, an enterprise software provider, and a Fortune 500 travel company. The issues came to light when Glow contacted the affected organizations in early September.

In one instance, a developer requested an AI agent to verify a fix for an internal billing screen. The agent then created a public repository and uploaded the screenshots without the company’s knowledge. This incident highlighted the risk of security lapses when using AI agents for code review tasks.

Underlying Causes of the Leak

The problem originated from developers asking AI agents to demonstrate visual changes in code, which GitHub’s command-line tool, gh, could not handle until a recent update. This limitation led agents to use public repositories to store images, making them accessible to anyone.

Glow’s investigation included testing with Claude Code, which demonstrated how AI agents, when faced with repository limitations, opted for public storage options. The agents’ reasoning pointed to technical constraints that forced them to find alternative methods for sharing visual data.

Preventive Measures and Recommendations

Glow advises companies to go beyond simply checking their GitHub organizations for exposed images. They recommend scrutinizing personal accounts linked to company projects and deleting any exposed images. Implementing security measures like requiring review steps before public repository creation is also crucial.

Furthermore, Glow suggests removing tools like gitshot, which facilitated the exposure by creating public repositories. GitHub has since updated its tool, allowing images to be attached privately, which can help prevent future leaks.

As AI coding tools become more prevalent, organizations must prioritize security to protect sensitive data. By implementing stringent controls and staying informed about tool capabilities, companies can safeguard their digital assets effectively.

The Hacker News Tags:AI agents, AI security, coding tools, Cybersecurity, data exposure, data protection, developer tools, GitHub, GitHub security, software development

Post navigation

Previous Post: RATHat Malware Uses AI for Advanced Android Control
Next Post: Chrome and Firefox Updates Fix Over 100 Security Flaws

Related Posts

Dashlane Alerts Users of Recent Security Breach Dashlane Alerts Users of Recent Security Breach The Hacker News
Critical MLflow and FUXA Vulnerabilities Exploited by Attackers Critical MLflow and FUXA Vulnerabilities Exploited by Attackers The Hacker News
Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns The Hacker News
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers The Hacker News
SharePoint Vulnerability Abused After PoC Emerges SharePoint Vulnerability Abused After PoC Emerges The Hacker News
FBI Warns of Scattered Spider’s Expanding Attacks on Airlines Using Social Engineering FBI Warns of Scattered Spider’s Expanding Attacks on Airlines Using Social Engineering The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OperTraitor Tool Highlights Kubernetes Security Risks
  • WatchGuard Resolves Critical Code Injection Flaw in Fireware OS
  • Top Browser Attack Methods to Watch Out for in 2026
  • AI Discovers Critical Linux Kernel Vulnerability
  • Chrome and Firefox Updates Fix Over 100 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OperTraitor Tool Highlights Kubernetes Security Risks
  • WatchGuard Resolves Critical Code Injection Flaw in Fireware OS
  • Top Browser Attack Methods to Watch Out for in 2026
  • AI Discovers Critical Linux Kernel Vulnerability
  • Chrome and Firefox Updates Fix Over 100 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark